Power communication data protection method and device for virtual power plant and storage medium
By constructing a multi-level data sensitivity assessment model and dynamic access control, combined with ABE encryption and multi-factor authentication, the security threats to the virtual power plant communication network were resolved, achieving efficient data protection and real-time assurance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-08
- Publication Date
- 2026-04-10
AI Technical Summary
Virtual power plant communication networks face multi-level and multi-domain collaborative data security threats. Traditional security mechanisms are difficult to adapt to dynamic, open, and high real-time requirements, and lack a systematic protection framework.
A multi-level data sensitivity assessment model based on entropy weight method is constructed, and encryption is performed using ABE technology. Dynamic permission management and multi-factor authentication are designed, and permission auditing is recorded using blockchain to achieve fine-grained control and adaptive protection.
It improves the data security of virtual power plants, reduces the probability of unauthorized access, optimizes the dynamic adaptation capability of security policies, and ensures communication efficiency and real-time performance.
Smart Images

Figure CN121841674A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power communication data security in virtual power plants, and specifically to a method, device, and storage medium for power communication data protection in virtual power plants. Background Technology
[0002] As the energy internet evolves towards digitalization and intelligence, virtual power plants, as key carriers for aggregating distributed energy resources and enabling flexible grid dispatch, are facing increasingly severe challenges to communication and data security. Power communication data carries the real-time operating status and control commands of the power grid; its integrity, confidentiality, and reliability directly determine the reliability and resilience of virtual power plant regulation. Currently, the communication network architecture of virtual power plants is characterized by multi-level, multi-domain collaboration, and massive access from heterogeneous terminals. Data faces multiple threats during collection, transmission, aggregation, and sharing, including eavesdropping, tampering, unauthorized access, and privacy leaks. Traditional security mechanisms based on boundary protection or static encryption are insufficient for the dynamic, open, and high-real-time communication environment, necessitating the construction of a new data protection system that balances fine-grained control with dynamic adaptive capabilities.
[0003] With the deep integration of edge computing, IoT, and 5G technologies into power systems, the scale and complexity of data interaction in virtual power plants continue to rise, placing higher demands on data classification, dynamic permission allocation, and identity authentication mechanisms. Existing research largely focuses on single technical paths, such as transmission encryption or access control, lacking a systematic protection framework from the perspective of the entire data lifecycle. There is a need to fundamentally construct a collaborative protection method that integrates data hierarchical identification and multi-factor authentication, based on information security governance theory and access control mechanisms, to enhance the inherent security capabilities of virtual power plants in open environments. Summary of the Invention
[0004] This invention addresses the shortcomings of existing technologies by providing a method, device, and storage medium for protecting power communication data in virtual power plants. It solves problems such as the difficulty in dynamically adapting security policies due to multi-source heterogeneous data streams, potential data consistency vulnerabilities in cross-layer protocol conversion, and the balance between security mechanisms and communication efficiency under high real-time requirements.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: A method for protecting power communication data in a virtual power plant includes the following steps: Collect raw operating data from various heterogeneous power terminals; Extract data features from raw operational data; By associating data features with the evaluation dimensions of data sensitivity, we obtain data attribute vectors corresponding to each evaluation dimension of data sensitivity; and by using the entropy weight method to assign weights to the data attribute vectors, we obtain the comprehensive sensitivity score of the running data. Based on the comprehensive sensitivity score, the operational data is divided into multiple data security levels; User attribute decision factors are set, including user personal attributes, resource attributes, environmental attributes, and operational attributes; the resource attributes include the data security level and business type; only when all user attribute decision factors meet the requirements will the user have the right to access the running data. For each successful access request, a time-limited session token is created to specify the validity period of the session.
[0006] To optimize the above technical solution, the specific measures also include: Furthermore, the data characteristics of the original operational data include business attributes, spatiotemporal characteristics, sharing scope, potential impact on the system, usage scenarios, flow paths, lifecycle stages, and security levels.
[0007] Furthermore, the dimensions for assessing data sensitivity include confidentiality requirements, criticality of integrity, real-time constraints, strength of business relevance, and scope of privacy impact; The specific steps for linking data features with the evaluation dimensions of data sensitivity are as follows: Confidentiality requirements are related to business attributes, sharing scope, potential impact on the system, lifecycle stage, and security level. The criticality of integrity is related to business attributes, spatiotemporal characteristics, and potential impact on the system; Real-time constraints are related to business attributes, spatiotemporal characteristics, usage scenarios, and flow paths; The strength of business association is related to business attributes, potential impact on the system, and lifecycle stage; The scope of privacy impact is related to business attributes, sharing scope, and lifecycle stage.
[0008] Furthermore, the specific steps of assigning weights to the data attribute vector using the entropy weight method are as follows:
[0009] in, A comprehensive sensitivity score for the data. For the first i The weights of each evaluation dimension satisfy the following: , For the first i Each dimension is for the data attribute vector x quantization function, nThe total number of dimensions is used to divide the running data into multiple data security levels based on the comprehensive sensitivity score. Specifically, the data is divided into core control level, important restricted level, and general sharing level. For data in the core control level, ABE technology is used for encryption. When encrypting data, the access policy is embedded in the ciphertext.
[0010] Furthermore, the environmental attributes include access time, geographical location, and network environment security score; the operational attributes include whether the requested action is "read" or "write," and the user only has the right to access the running data when all user attribute decision factors meet the requirements is expressed by the following formula:
[0011] In the formula, For user access permissions, The user has the right to access the running data only when all attribute decision factors are 1 and Q is 1.
[0012] Furthermore, the user's personal attributes use mutually independent authentication factors for dynamic identity verification. The authentication factors include knowledge factors, holding factors, and attribute factors. The knowledge factors include user passwords and PIN codes, the holding factors include smart cards, hardware tokens, and mobile devices, and the attribute factors include behavioral characteristics and device fingerprints. The dynamic identity authentication specifically refers to: The risk engine assesses the security status of the current session in real time. The assessment dimensions include the reputation of the login IP address, whether the login time is during a common time period, whether the device fingerprint matches the historical records, and whether there is abnormal traffic in the network environment. It also calculates the risk score in real time and dynamically determines the factor strength required for this authentication. For low-risk sessions with a risk score below the threshold, only two-factor authentication is required. For high-risk sessions with a risk score equal to or greater than the threshold, more factor verification is automatically triggered, or biometric identification or manual review is required. If the authentication is successful, the user's personal attribute value is set to 1.
[0013] Furthermore, the method also includes an access control audit and traceability process. All access control granting, use, modification, and revocation operations must be recorded in an immutable log. The immutability of blockchain is used to store the logs for auditing, and the method supports querying and analysis by multiple dimensions such as time, user, and data resources. By continuously analyzing the audit logs, the access control policy can be further optimized.
[0014] Furthermore, the session token embeds the specific scope of authorized access permissions, and the validity period of the session is dynamically adjusted based on the risk assessment results.
[0015] The present invention also proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the power communication data protection method for virtual power plants as described above.
[0016] The present invention also proposes a computer-readable storage medium storing a computer program that enables a computer to execute the power communication data protection method for virtual power plants as described above.
[0017] The beneficial effects of this invention are: This invention constructs a four-layer communication data architecture for virtual power plants, flexibly collecting power communication data. Based on power business characteristics and data sensitivity, it builds a dynamic and refined multi-level classification model to assess data sensitivity, enabling rapid identification and hierarchical division of communication data. It designs differentiated access control strategies, using attribute-based encryption and dynamic authorization mechanisms to restrict unnecessary data access, enhancing effective data protection. It integrates user behavior characteristics and device status information to construct a lightweight multi-factor authentication model, effectively improving account protection against misuse. To a certain extent, it solves the problem of dynamic adaptation of security policies caused by multi-source heterogeneous data streams; potential data consistency vulnerabilities in cross-layer protocol conversion; and the balance between security mechanisms and communication efficiency under high real-time requirements. In typical attack scenarios, it effectively reduces the probability of unauthorized data access, improves the overall system security baseline, and provides a feasible solution for data security governance in virtual power plants. Attached Figure Description
[0018] Figure 1 This is a flowchart of a power communication data protection method for virtual power plants.
[0019] Figure 2 The virtual power plant uses a four-layer data structure.
[0020] Figure 3 This is a comparison chart of load forecast results.
[0021] Figure 4 This is a time series comparison chart of prediction errors. Detailed Implementation
[0022] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0023] Example 1 This invention proposes a method for protecting power communication data in virtual power plants. The process of this method is as follows: Figure 1 As shown, it includes the following steps: This invention collects raw operational data from various heterogeneous power terminals. Based on massive amounts of data, it constructs a four-layer communication data architecture for a virtual power plant, including a perception layer, a network layer, a platform layer, and an application layer, specifically as follows: Figure 2 As shown.
[0024] The perception layer consists of a massive number of heterogeneous terminal devices, including distributed photovoltaic inverters, wind power monitoring units, energy storage converters, smart meters, and electric vehicle charging piles, which are responsible for collecting raw operating data and receiving control commands.
[0025] The network layer relies on power fiber optic private networks, wireless public networks, or hybrid communication technologies to realize data forwarding between terminals and aggregation substations, and between substations and the main station.
[0026] The platform layer serves as the central hub for data aggregation and processing, undertaking data cleaning, storage, fusion, and lightweight computing functions.
[0027] The application layer provides data access interfaces and visualization support for business scenarios such as scheduling decisions, market transactions, and user services.
[0028] Extract data features from raw operational data. These features include business attributes, spatiotemporal characteristics, sharing scope, potential impact on the system, usage scenarios, flow paths, lifecycle stages, and security levels. Convert the received data into a format that facilitates feature extraction and data hierarchy classification later. The specific format is as follows:
[0029] By associating data features with the evaluation dimensions of data sensitivity, we obtain the data attribute vector corresponding to each evaluation dimension of data sensitivity. The evaluation dimensions of data sensitivity include confidentiality requirements, integrity criticality, real-time constraints, business relevance strength, and privacy impact scope. The specific steps for linking data characteristics with the evaluation dimensions of data sensitivity are as follows: Confidentiality requirements are related to business attributes, sharing scope, potential impact on the system, lifecycle stage, and security level. The criticality of integrity is related to business attributes, spatiotemporal characteristics, and potential impact on the system; Real-time constraints are related to business attributes, spatiotemporal characteristics, usage scenarios, and flow paths; The strength of business association is related to business attributes, potential impact on the system, and lifecycle stage; The scope of privacy impact is related to business attributes, sharing scope, and lifecycle stage.
[0030] The relationship between data features and data sensitivity assessment dimensions is shown in the table below:
[0031] Determining data sensitivity depends not only on its content (such as whether it contains geographic information of critical infrastructure or real-time control commands), but also on the data's usage scenario, flow path, and lifecycle stage. For example, the same set of power generation forecast data may be highly sensitive during the day-ahead market bidding phase, but may become general data after historical archiving.
[0032] Each data sensitivity dimension can be further refined into several quantifiable indicators. For example, the confidentiality dimension can be classified according to the economic losses or social impacts that data leakage may cause.
[0033] To avoid bias caused by subjective weighting, the entropy weighting method is used to assign weights to the data attribute vectors, resulting in a comprehensive sensitivity score for the operational data; specifically:
[0034] in, A comprehensive sensitivity score for the data. For the first i The weights of each evaluation dimension satisfy the following: , The sensitivity score can be determined based on expert scoring or learning from historical data. In practical use, evaluation dimension weight templates for different types of business data can be preset. When new data comes in, the system automatically extracts its attribute features and calls the formula to calculate the sensitivity score, thereby automating and standardizing the classification process. For the first i Each dimension is for the data attribute vector x quantization function, n This represents the total number of dimensions.
[0035] Based on the comprehensive sensitivity score, the operational data is divided into multiple data security levels; specifically, they are divided into core control level, important restricted level, and general sharing level. For data in the core control level, ABE technology is used for encryption, and the access policy is embedded in the ciphertext when encrypting the data.
[0036]
[0037] Establish a dynamic data sensitivity adjustment mechanism: when the system detects an increase in network attack activity, temporarily increase the security level of data that has a significant potential impact on the system; when data is aggregated and de-identified, reduce its sensitivity; reduce the sensitivity of data at the end of its lifecycle.
[0038] User attribute decision factors are set, including user personal attributes, resource attributes, environmental attributes, and operational attributes. Resource attributes include data security level and business type; environmental attributes include access time, geographical location, and network environment security score; operational attributes include whether the requested action is "read" or "write." Only when all user attribute decision factors meet the requirements does the user have permission to access running data. This can be expressed by the following formula:
[0039] In the formula, For user access permissions, The user has the right to access the running data only when all attribute decision factors are 1 and Q is 1.
[0040] User personal attributes use mutually independent authentication factors for dynamic identity verification. The authentication factors include knowledge factors, holding factors, and attribute factors. The knowledge factors include user passwords and PIN codes, the holding factors include smart cards, hardware tokens, and mobile devices, and the attribute factors include behavioral characteristics and device fingerprints. The dynamic identity authentication specifically refers to: The risk engine assesses the security status of the current session in real time. The assessment dimensions include the credibility of the login IP address, whether the login time is during a common time period, whether the device fingerprint matches the historical records, and whether there is abnormal traffic in the network environment. It also calculates the risk score in real time and dynamically determines the factor strength required for this authentication. For low-risk sessions with a risk score below the threshold (such as access from a trusted intranet or a commonly used device), only two-factor authentication is required. For high-risk sessions with a risk score equal to or greater than the threshold (such as login attempts from an unfamiliar region or an uncommon device), more factor verification is automatically triggered, or biometric identification or manual review is required. If the authentication is successful, the user's personal attribute value is set to 1.
[0041] The system architecture mainly includes an authentication client, an authentication server, a risk decision engine, and a credential management module. The authentication client is integrated into the user's terminal or device agent program, responsible for collecting authentication factors (such as passwords and fingerprints) or environmental data (such as device identifiers) submitted by the user. The authentication server, as the core hub, receives authentication requests submitted by the client and calls the risk decision engine for real-time analysis. The risk decision engine has a built-in lightweight machine learning model that can continuously learn the behavioral patterns of normal users based on historical authentication logs, thereby more accurately identifying anomalies. The credential management module is responsible for securely storing and updating various authentication credentials and using secure hardware modules to protect key materials.
[0042] For example, a policy might stipulate: "Data query operations are only allowed when the user is a 'dispatcher', the accessed device data security level is below 'Important Restricted', the current network threat level is 'Low', and the access source IP is located in a trusted zone within the internal network." A time-limited session token is created for each successful access request to define the session's validity period. The session token embeds the specific scope of authorized permissions, and its validity period is dynamically adjusted based on risk assessment results. For example, when the system intrusion detection module detects abnormal login behavior or increased network attack activity, it can automatically shorten the validity period of all active sessions, forcing re-authentication. Conversely, during low-risk periods, the session time can be appropriately extended to improve user experience.
[0043] The method of this invention also includes a permission auditing and traceability process. All permission granting, usage, modification, and revocation operations must be recorded in an immutable log. The immutability of blockchain is used to store the audit logs, which support querying and analysis by multiple dimensions, including time, user, and data resources. This not only meets compliance requirements but also provides crucial evidence for post-incident security incident analysis. Continuous analysis of the audit logs allows for further optimization of permission policies. For example, permissions that have not been used for a long time can be revoked, or abnormal permission usage patterns can be identified and alerted promptly.
[0044] Example 2 This invention proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the power communication data protection method for virtual power plants as described in Embodiment 1.
[0045] Example 3 This invention proposes a computer-readable storage medium storing a computer program that causes a computer to execute the power communication data protection method for a virtual power plant as described in Embodiment 1.
[0046] In the embodiments disclosed in this application, a computer storage medium may be a tangible medium that may contain or store programs for use by or in conjunction with an instruction execution system, apparatus, or device. The computer storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of computer storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0047] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0048] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should be considered within the scope of protection of the present invention.
Claims
1. A method for protecting power communication data in a virtual power plant, characterized in that, Includes the following steps: Collect raw operating data from various heterogeneous power terminals; Extract data features from raw operational data; By associating data features with the evaluation dimensions of data sensitivity, we obtain data attribute vectors corresponding to each evaluation dimension of data sensitivity; and by using the entropy weight method to assign weights to the data attribute vectors, we obtain the comprehensive sensitivity score of the running data. Based on the comprehensive sensitivity score, the operational data is divided into multiple data security levels; User attribute decision factors are set, including user personal attributes, resource attributes, environmental attributes, and operational attributes; the resource attributes include the data security level and business type; only when all user attribute decision factors meet the requirements will the user have the right to access the running data. For each successful access request, a time-limited session token is created to specify the validity period of the session.
2. The power communication data protection method for virtual power plants as described in claim 1, characterized in that, The data characteristics of the original operational data include business attributes, spatiotemporal characteristics, sharing scope, potential impact on the system, usage scenarios, flow paths, lifecycle stages, and security levels.
3. The power communication data protection method for virtual power plants as described in claim 1, characterized in that, The dimensions for assessing data sensitivity include confidentiality requirements, criticality of integrity, real-time constraints, strength of business relevance, and scope of privacy impact. The specific steps for linking data features with the evaluation dimensions of data sensitivity are as follows: Confidentiality requirements are related to business attributes, sharing scope, potential impact on the system, lifecycle stage, and security level. The criticality of integrity is related to business attributes, spatiotemporal characteristics, and potential impact on the system; Real-time constraints are related to business attributes, spatiotemporal characteristics, usage scenarios, and flow paths; The strength of business association is related to business attributes, potential impact on the system, and lifecycle stage; The scope of privacy impact is related to business attributes, sharing scope, and lifecycle stage.
4. The power communication data protection method for virtual power plants as described in claim 1, characterized in that, The specific steps of assigning weights to data attribute vectors using the entropy weighting method are as follows: in, A comprehensive sensitivity score for the data. For the first i The weights of each evaluation dimension satisfy the following: , For the first i Each dimension is for the data attribute vector x quantization function, n The total number of dimensions is used to divide the running data into multiple data security levels based on the comprehensive sensitivity score. Specifically, the data is divided into core control level, important restricted level, and general sharing level. For data in the core control level, ABE technology is used for encryption. When encrypting data, the access policy is embedded in the ciphertext.
5. The power communication data protection method for virtual power plants as described in claim 1, characterized in that, The environmental attributes include access time, geographical location, and network security score; the operational attributes include whether the requested action is "read" or "write"; the user only has the right to access running data when all user attribute decision factors meet the requirements, which is expressed by the following formula: In the formula, For user access permissions, The user has the right to access the running data only when all attribute decision factors are 1 and Q is 1.
6. The power communication data protection method for virtual power plants as described in claim 5, characterized in that, The user's personal attributes use mutually independent authentication factors for dynamic identity verification. The authentication factors include knowledge factors, holding factors, and attribute factors. The knowledge factors include user passwords and PIN codes, the holding factors include smart cards, hardware tokens, and mobile devices, and the attribute factors include behavioral characteristics and device fingerprints. The dynamic identity authentication specifically refers to: The risk engine assesses the security status of the current session in real time. The assessment dimensions include the reputation of the login IP address, whether the login time is during a common time period, whether the device fingerprint matches the historical records, and whether there is abnormal traffic in the network environment. It also calculates the risk score in real time and dynamically determines the factor strength required for this authentication. For low-risk sessions with a risk score below the threshold, only two-factor authentication is required. For high-risk sessions with a risk score equal to or greater than the threshold, more factor verification is automatically triggered, or biometric identification or manual review is required. If the authentication is successful, the user's personal attribute value is set to 1.
7. The power communication data protection method for virtual power plants as described in claim 1, characterized in that, The method also includes an access control audit and traceability process. All access control granting, use, modification and revocation operations must be recorded in an immutable log. The immutability of blockchain is used to store the logs for auditing, and the method supports querying and analysis by multiple dimensions such as time, user and data resources. By continuously analyzing the audit logs, the access control policy can be further optimized.
8. The power communication data protection method for virtual power plants as described in claim 1, characterized in that, The session token contains the specific scope of authorized access permissions, and the validity period of the session is dynamically adjusted based on the risk assessment results.
9. An electronic device, characterized in that, include: The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the power communication data protection method for a virtual power plant as described in any one of claims 1-8.
10. A computer-readable storage medium storing a computer program, characterized in that, The computer program causes the computer to execute the power communication data protection method for virtual power plants as described in any one of claims 1-8.